Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeSave to Reflect
Findings · 3
MEDIUM FINDINGS · 3
  1. 01When Kindle sync is enabled, background SW fetches the user's full Kindle library catalog and per-book notes/highlights from read.amazon.com using the user's logged-in browser cookies (credentials: 'include'), then uploads the aggregated highlights to reflect.app.
  2. 02On user save action (Cmd+Shift+P / context menu / toolbar), extension collects current page URL, document.title, og:title/og:description, meta description, and any selected text/HTML and POSTs it to reflect.app via the user's authenticated session.
  3. 03Content script declared with matches:['<all_urls>'] runs on every page and opens a long-lived chrome.runtime.connect port, posting the current page URL to the background SW on every navigation so the SW can look up whether the URL has a saved link in linkStore.
OTHER EXTENSIONS

Is Save to Reflect safe?

Clean risk

No summary available.

Reflect App, LLCv1.6.5Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026app.reflect.SaveToReflect.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact